Here is the combofix log:
ComboFix 07-11-08.1 - Owner 2007-11-14 18:06:01.5 - NTFSx86
Microsoft Windows XP Home Edition 5.1.2600.2.1252.1.1033.18.175 [GMT -5:00]
Running from: C:\Documents and Settings\Owner\Desktop\ComboFix.exe
Command switches used :: C:\Documents and Settings\Owner\Desktop\CFScript.txt
* Created a new restore point
FILE
C:\Documents and Settings\Owner\pdf.exe
C:\WINDOWS\Fonts\Setup.exe
C:\WINDOWS\system32\fccdayy.dll
C:\WINDOWS\system32\hkwvoiwj.dll
C:\WINDOWS\system32\hmnnygna.dll
C:\WINDOWS\system32\jkhhi.dll
C:\WINDOWS\system32\kcdqgkmk.dll
C:\WINDOWS\system32\uisbbuwp.dll
C:\WINDOWS\system32\vbzip10.dll
.
Unable to gain System Privileges
((((((((((((((((((((((((((((((((((((((( Other Deletions )))))))))))))))))))))))))))))))))))))))))))))))))
.
C:\Documents and Settings\Owner\Application Data\BitTorrent
C:\Documents and Settings\Owner\Application Data\BitTorrent\dht.dat
C:\Documents and Settings\Owner\Application Data\BitTorrent\resume.dat
C:\Documents and Settings\Owner\Application Data\BitTorrent\resume.dat.old
C:\Documents and Settings\Owner\Application Data\BitTorrent\settings.dat
C:\Documents and Settings\Owner\Application Data\BitTorrent\settings.dat.old
C:\Documents and Settings\Owner\Application Data\BitTorrent\Warhammer 40K Collection.torrent
C:\Documents and Settings\Owner\Application Data\LimeWire
C:\Documents and Settings\Owner\Application Data\LimeWire\414splashfree.png
C:\Documents and Settings\Owner\Application Data\LimeWire\createtimes.cache
C:\Documents and Settings\Owner\Application Data\LimeWire\fileurns.bak
C:\Documents and Settings\Owner\Application Data\LimeWire\fileurns.cache
C:\Documents and Settings\Owner\Application Data\LimeWire\filters.props
C:\Documents and Settings\Owner\Application Data\LimeWire\gnutella.net
C:\Documents and Settings\Owner\Application Data\LimeWire\installation.props
C:\Documents and Settings\Owner\Application Data\LimeWire\library.dat
C:\Documents and Settings\Owner\Application Data\LimeWire\limewire.props
C:\Documents and Settings\Owner\Application Data\LimeWire\mojito.props
C:\Documents and Settings\Owner\Application Data\LimeWire\questions.props
C:\Documents and Settings\Owner\Application Data\LimeWire\responses.cache
C:\Documents and Settings\Owner\Application Data\LimeWire\simpp.xml
C:\Documents and Settings\Owner\Application Data\LimeWire\spam.dat
C:\Documents and Settings\Owner\Application Data\LimeWire\tables.props
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme.lwtp
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\01_star.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\02_star.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\03_star.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\04_star.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\05_star.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\chat.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\forward_dn.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\forward_up.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\kill.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\kill_on.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\logo.png
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\notsearching.png
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\pause_dn.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\pause_up.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\play_dn.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\play_up.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\question.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\rewind_dn.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\rewind_up.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\searching.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\splash.png
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\splashpro.png
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\stop_dn.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\stop_up.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\theme.txt
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\version.txt
C:\Documents and Settings\Owner\Application Data\LimeWire\themes\windows_theme\warning.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\ttree.cache
C:\Documents and Settings\Owner\Application Data\LimeWire\version.xml
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\data\audio.sxml
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\data\delete_me
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\misc\application.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\misc\audio.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\misc\document.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\misc\image.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\misc\video.gif
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\schemas\application.xsd
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\schemas\audio.xsd
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\schemas\document.xsd
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\schemas\image.xsd
C:\Documents and Settings\Owner\Application Data\LimeWire\xml\schemas\video.xsd
C:\Documents and Settings\Owner\Application Data\uTorrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Cossacks European Wars.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Cossacks the Art of War.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\dht.dat
C:\Documents and Settings\Owner\Application Data\uTorrent\dht.dat.old
C:\Documents and Settings\Owner\Application Data\uTorrent\Great Invasions [Multilenguaje-EN-SP-FR-DE][www.pctorrent.com].torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Great.Invasions-RELOADED.[www.extreme-torrent.dl.am].torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Heroes of Might and Magic 3.rar.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\resume.dat
C:\Documents and Settings\Owner\Application Data\uTorrent\resume.dat.old
C:\Documents and Settings\Owner\Application Data\uTorrent\rss.dat
C:\Documents and Settings\Owner\Application Data\uTorrent\settings.dat
C:\Documents and Settings\Owner\Application Data\uTorrent\settings.dat.old
C:\Documents and Settings\Owner\Application Data\uTorrent\SuperPower 2[2CDS][english][www.pctorrent.com].torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\utorrent.lng
C:\Documents and Settings\Owner\Application Data\uTorrent\Warhammer 40,000 - Dawn of War.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Warhammer.1.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Warhammer.2.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Warhammer.3.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Warhammer.4.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Warhammer.5.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\warhammer.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\WORMS-Rar.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Worms 2.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Worms Armageddon.1.torrent
C:\Documents and Settings\Owner\Application Data\uTorrent\Worms Armageddon.torrent
C:\Documents and Settings\Owner\pdf.exe
C:\Program Files\BitTorrent
C:\Program Files\Program Files
C:\Program Files\Program Files\RemovalPro\InCode Solutions\RemoveIT Pro v4-Trial\files.dat
C:\Program Files\Program Files\RemovalPro\InCode Solutions\RemoveIT Pro v4-Trial\INSTALL.LOG
C:\Program Files\Program Files\RemovalPro\InCode Solutions\RemoveIT Pro v4-Trial\list.htm
C:\Program Files\Program Files\RemovalPro\InCode Solutions\RemoveIT Pro v4-Trial\main.ico
C:\Program Files\Program Files\RemovalPro\InCode Solutions\RemoveIT Pro v4-Trial\Readme.txt
C:\Program Files\Program Files\RemovalPro\InCode Solutions\RemoveIT Pro v4-Trial\RegBase.rgk
C:\Program Files\Program Files\RemovalPro\InCode Solutions\RemoveIT Pro v4-Trial\removeit.exe
C:\Program Files\Program Files\RemovalPro\InCode Solutions\RemoveIT Pro v4-Trial\UNWISE.EXE
C:\WINDOWS\Fonts\Setup.exe
C:\WINDOWS\system32\awvtu.dll
C:\WINDOWS\system32\fccdayy.dll
C:\WINDOWS\system32\hmnnygna.dll
C:\WINDOWS\system32\kcdqgkmk.dll
C:\WINDOWS\system32\utvwa.ini
C:\WINDOWS\system32\utvwa.ini2
C:\WINDOWS\system32\vbzip10.dll
.
((((((((((((((((((((((((( Files Created from 2007-10-14 to 2007-11-14 )))))))))))))))))))))))))))))))
.
2007-11-13 15:14 51,200 --a------ C:\WINDOWS\NirCmd.exe
2007-11-13 14:54 <DIR> d-------- C:\Program Files\Enigma Software Group
2007-11-13 14:45 <DIR> d-------- C:\Documents and Settings\Owner\Application Data\AdwareAlert
2007-11-13 00:02 <DIR> d--h----- C:\WINDOWS\PIF
2007-11-12 17:49 <DIR> d-------- C:\Program Files\GiPo@Utilities
2007-11-12 17:49 <DIR> d-------- C:\Program Files\Common Files\Gibinsoft Shared
2007-11-12 16:30 <DIR> d-------- C:\Program Files\RemoveITPro
2007-11-12 15:22 <DIR> d-------- C:\RemoveITPro
2007-11-12 01:24 <DIR> d-------- C:\Documents and Settings\Administrator.NEWROOMPC\Application Data\InterTrust
2007-11-12 01:23 <DIR> d-------- C:\Documents and Settings\Administrator.NEWROOMPC\WINDOWS
2007-11-12 01:23 <DIR> d-------- C:\Documents and Settings\Administrator.NEWROOMPC\Application Data\VERITAS
2007-11-12 01:23 <DIR> d-------- C:\Documents and Settings\Administrator.NEWROOMPC\Application Data\Symantec
2007-11-12 01:23 <DIR> d-------- C:\Documents and Settings\Administrator.NEWROOMPC\Application Data\Share-to-Web Upload Folder
2007-11-08 23:07 <DIR> d-------- C:\Documents and Settings\LocalService\Application Data\Symantec
2007-11-07 05:11 <DIR> d--h----- C:\Program Files\Zero G Registry
2007-11-07 05:11 <DIR> d-------- C:\Program Files\Project64 v1.5
2007-11-07 05:11 <DIR> d-------- C:\Documents and Settings\Owner\Shared
2007-11-07 05:11 <DIR> d-------- C:\Documents and Settings\Owner\Incomplete
2007-10-31 16:24 <DIR> d-------- C:\Program Files\Common Files\Apple
2007-10-20 19:59 <DIR> d-------- C:\Documents and Settings\All Users\Application Data\Apple
.
(((((((((((((((((((((((((((((((((((((((( Find3M Report ))))))))))))))))))))))))))))))))))))))))))))))))))))
.
2007-11-14 06:27 --------- d-----w C:\Program Files\Common Files\Symantec Shared
2007-11-12 04:06 --------- d-----w C:\Program Files\Windows Live Toolbar
2007-11-12 02:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Viewpoint
2007-11-09 06:00 --------- d-----w C:\Documents and Settings\All Users\Application Data\Spybot - Search & Destroy
2007-11-07 10:11 --------- d-----w C:\Program Files\Google
2007-11-06 19:39 --------- d-----w C:\Program Files\AtBackup
2007-11-06 19:20 --------- d-----w C:\Program Files\Norton AntiVirus
2007-11-05 18:38 --------- d-----w C:\Program Files\iTunes
2007-10-31 21:31 --------- d-----w C:\Program Files\iPod
2007-10-31 21:28 --------- d-----w C:\Program Files\QuickTime
2007-10-28 18:50 --------- d-----w C:\Program Files\Java
2007-10-25 20:08 --------- d-----w C:\Program Files\Common Files\Adobe
2007-10-21 01:11 --------- d-----w C:\Program Files\Picasa2
2007-10-21 00:59 --------- d-----w C:\Program Files\Apple Software Update
2007-10-20 17:59 --------- d-----w C:\Program Files\Gamesgate Games
2007-10-07 18:35 --------- d-----w C:\Program Files\TripleA
2007-10-07 16:30 --------- d--h--w C:\Program Files\InstallShield Installation Information
2006-03-01 22:27 75,200 ----a-w C:\Documents and Settings\Owner\Application Data\GDIPFONTCACHEV1.DAT
.
((((((((((((((((((((((((((((((((((((( Reg Loading Points ))))))))))))))))))))))))))))))))))))))))))))))))))
.
.
*Note* empty entries & legit default entries are not shown
[HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"hpsysdrv"="c:\windows\system\hpsysdrv.exe" [1998-05-07 18:04]
"CamMonitor"="c:\Program Files\Hewlett-Packard\Digital Imaging\Unload\hpqcmon.exe" [2002-06-18 01:11]
"KBD"="C:\HP\KBD\KBD.EXE" [2001-07-06 23:56]
"StorageGuard"="C:\Program Files\VERITAS Software\Update Manager\sgtray.exe" [2002-05-09 10:01]
"DDCM"="C:\Program Files\WildTangent\DDC\DDCManager\DDCMan.exe" [2002-06-08 03:18]
"DDCActiveMenu"="C:\Program Files\WildTangent\DDC\ActiveMenu\DDCActiveMenu.exe" [2002-06-08 03:20]
"Recguard"="C:\WINDOWS\SMINST\RECGUARD.EXE" [2001-12-19 01:39]
"IgfxTray"="C:\WINDOWS\System32\igfxtray.exe" [2002-05-15 05:29]
"HotKeysCmds"="C:\WINDOWS\System32\hkcmd.exe" [2002-05-15 05:20]
"HPDJ Taskbar Utility"="C:\WINDOWS\System32\spool\drivers\w32x86\3\hpztsb05.exe" [2002-05-22 01:28]
"LTMSG"="LTMSG.exe" [2003-07-14 10:52 C:\WINDOWS\ltmsg.exe]
"NeroFilterCheck"="C:\WINDOWS\system32\NeroCheck.exe" [2001-07-09 10:50]
"RemoteControl"="C:\Program Files\CyberLink\PowerDVD\PDVDServ.exe" [2003-12-08 17:35]
"ccApp"="C:\Program Files\Common Files\Symantec Shared\ccApp.exe" [2007-01-09 17:32]
"Symantec NetDriver Monitor"="C:\PROGRA~1\SYMNET~1\SNDMon.exe" [2007-04-03 19:07]
"LiveState Recovery 3.0"="C:\Program Files\Symantec\LiveState Recovery\Desktop 3.0\Agent\VProTray.exe" [2004-12-07 16:59]
"SunJavaUpdateSched"="C:\Program Files\Java\jre1.6.0_03\bin\jusched.exe" [2007-09-25 00:11]
"Adobe Reader Speed Launcher"="C:\Program Files\Adobe\Reader 8.0\Reader\Reader_sl.exe" [2007-10-10 18:51]
"QuickTime Task"="C:\Program Files\QuickTime\qttask.exe" [2007-06-29 05:24]
"iTunesHelper"="C:\Program Files\iTunes\iTunesHelper.exe" [2007-09-26 13:42]
"PS2"="C:\WINDOWS\system32\ps2.exe" [2002-06-14 18:39]
"nwiz"="nwiz.exe" [2002-05-03 19:06 C:\WINDOWS\system32\nwiz.exe]
[HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run]
"ctfmon.exe"="C:\WINDOWS\system32\ctfmon.exe" [2004-08-04 02:56]
[HKEY_USERS\.default\software\microsoft\windows\currentversion\run]
"Picasa Media Detector"=C:\Program Files\Picasa2\PicasaMediaDetector.exe
C:\Documents and Settings\Owner\Start Menu\Programs\Startup\
Adobe Gamma.lnk - C:\Program Files\Common Files\Adobe\Calibration\Adobe Gamma Loader.exe [2005-03-16 19:16:50]
Event Reminder.lnk - C:\pmw\PMREMIND.EXE [1997-08-06 11:21:00]
Palm Registration.lnk - C:\Palm\register.exe [2005-08-08 12:36:14]
C:\Documents and Settings\All Users\Start Menu\Programs\Startup\
DataViz Inc Messenger.lnk - C:\Program Files\Common Files\DataViz\DvzIncMsgr.exe [2006-01-06 19:52:03]
Event Planner Reminders Tray Icon.lnk - C:\Sierra\Planner\PLNRnote.exe [2005-02-26 09:28:39]
HOTSYNCSHORTCUTNAME.lnk - C:\Palm\Hotsync.exe [2004-06-09 14:27:34]
NDAS Device Management.lnk - C:\Program Files\NDAS\System\ndasmgmt.exe [2007-01-17 18:18:22]
.
Contents of the 'Scheduled Tasks' folder
"2007-11-13 19:45:26 C:\WINDOWS\Tasks\AdwareAlert Scheduled Scan.job"
- C:\Program Files\AdwareAlert\AdwareAlert.exe
"2007-11-08 01:39:07 C:\WINDOWS\Tasks\AppleSoftwareUpdate.job"
- C:\Program Files\Apple Software Update\SoftwareUpdate.exe
"2007-11-14 22:50:01 C:\WINDOWS\Tasks\Check Updates for Windows Live Toolbar.job"
- C:\Program Files\Windows Live Toolbar\MSNTBUP.EXE
"2007-11-10 01:01:12 C:\WINDOWS\Tasks\Norton AntiVirus - Scan my computer - Owner.job"
- C:\PROGRA~1\NORTON~1\Navw32.exe
.
**************************************************************************
catchme 0.3.1250 W2K/XP/Vista - rootkit/stealth malware detector by Gmer, http://www.gmer.net
Rootkit scan 2007-11-14 18:23:35
Windows 5.1.2600 Service Pack 2 NTFS
scanning hidden processes ...
scanning hidden autostart entries ...
scanning hidden files ...
scan completed successfully
hidden files: 0
**************************************************************************
.
Completion time: 2007-11-14 18:34:47 - machine was rebooted
C:\ComboFix2.txt ... 2007-11-14 11:38
.
--- E O F ---